MCPA-2026-0012
highrce-vectorsCVSS 8.4
Flyto2 Core unauthenticated command execution via HTTP MCP execute_module (CVE-2026-55786)
flyto-core versions 2.26.2 before 2.26.4 expose an execute_module operation on the HTTP MCP surface without authentication: a caller who can reach the HTTP listener can invoke arbitrary Flyto modules, including ones that run shell commands, without any credential. Fixed in 2.26.4.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | flyto-core | >= 2.26.2, < 2.26.4 |
Identifiers
CVE-2026-55786GHSA-h9f9-h6gm-wc85PYSEC-2026-2482CWE-78CWE-306
References
- advisory https://github.com/advisories/GHSA-h9f9-h6gm-wc85
- web https://osv.dev/vulnerability/PYSEC-2026-2482
- web https://nvd.nist.gov/vuln/detail/CVE-2026-55786
Timeline
- Published: 2026-07-06